11.10.2013 Views

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

Risk Management Manual of Examination Policies - FDIC

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OTHER PERTINENT INFORMATION (Continued)<br />

In addition to the security measures delineated below, the Applicant is contracting with Aurum, an entity that has attained the requisite<br />

SAS 70 certification. This certification, rendered by an independent accounting firm, affirms that a provider’s computer systems are<br />

being managed and operated in a manner consistent with accepted industry practices.<br />

Security measures proposed for the fully transactional web channel include the following:<br />

Encrypted Transactions<br />

All banking and Internet communications will be encrypted. This will preclude sensitive financial data from being easily read and/or<br />

deciphered. Encryption will be accomplished via the use <strong>of</strong> Secure Sockets Layer Technology. This technology, considered the<br />

standard for encryption, is currently utilized by large nationally recognized web browsers. Data transmission from the Applicant’s<br />

server and Aurum will be encrypted using Data Encryption Standard (DES) encryption, as further described below.<br />

Secure Logon<br />

To preclude the possibility <strong>of</strong> a third party downloading the Applicant’s or a customer’s password file, user identification and<br />

passwords will be encrypted and stored on a separate database server, not on the Internet or the web server. In addition, password<br />

parameters will be structured in a format, which makes the probability <strong>of</strong> randomly acquiring or guessing said password, extremely<br />

low.<br />

Isolated Bank Server<br />

The computer used to provide the Applicant’s services would not be directly accessed via the Internet. It will be on a private<br />

connection, or intranet, that provides two-way communication between the isolated bank server and Internet server. Consequently, an<br />

Internet user will be prevented from accessing the computer that provides the Applicant’s services. All banking services will be<br />

routed from the Internet server through a firewall. The firewall is a combination <strong>of</strong> s<strong>of</strong>tware and hardware devices that specifically<br />

defines, controls, and limits access to internal computers from outside computers across a network. The firewall framework means<br />

that only authenticated bank customers or administrators may send or receive transactions through it. The firewall will also be<br />

immune to penetration from within the network. All messages transmitted or received between the Internet server and the operating<br />

server will be encrypted using DES encryption.<br />

This consists <strong>of</strong> a symmetric key algorithm. Such technology is highly secure as it is not vulnerable to standard ciphertext attacks.<br />

Therefore, even if an individual was to route a message to the Applicant’s server and through the firewall, the message could not be<br />

encrypted in a manner, which would be considered valid by the server. Consequently, the Applicant’s server would reject the<br />

message.<br />

Authenticated Session Integrity<br />

An authenticated user pertains to any user who signs onto the Applicant’s web site with a valid user ID and password. The<br />

Applicant’s server will be configured to limit exposure to authenticated users who attempt to defraud it. If an authenticated user alters<br />

a command (URL), which is sent from the web browser to the server, in any way in an attempt to gain access to another user’s<br />

account, the Applicant’s server immediately detects that the session integrity variables have been violated. Once detected, the<br />

Applicant’s server will terminate the session and record the unsuccessful attempt in a log so that staff can investigate.<br />

Physical Security & Secure Modem Access<br />

All servers and network computers will reside in secure facilities. Computer operations supporting the Applicant’s internet access will<br />

also reside in secure back-up facilities. Only employees with a valid access card may enter the physical premises. Access to server<br />

systems will require further password authentication. A private line, which is not accessible by or from the public, will connect the<br />

Applicant’s server with Aurum. A dial-up maintenance port will also permit access to the server. The modem that provides the only<br />

access to this port will be specially protected and will only be enabled when necessary.<br />

<strong>FDIC</strong> 6510/10 (02-2002) 40

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!